Req #72235 [Opn->Dup]: PDO and certificate CN
Edit report at https://bugs.php.net/bug.php?id=72235&edit=1
ID: 72235
Updated by: requinix@php.net
Reported by: ghfjdksl at gmail dot com
Summary: PDO and certificate CN
-Status: Open
+Status: Duplicate
Type: Feature/Change Request
Package: PDO MySQL
Operating System: rhel 6.7
PHP Version: 5.6.21
Block user comment: N
Private report: N
New Comment:
Duplicate of bug #71845 and related to request #71003.
Previous Comments:
------------------------------------------------------------------------
[2016-05-18 01:42:24] ghfjdksl at gmail dot com
Description:
------------
In php 5.6, certificate CN is verified by default. But this is infeasible in some situation. There
should be at least one attribute that can toggle the CN verification on and off, or at least let the
user specify what the expected CN is, instead of using the connection url. There is a flag that one
can set for mysqli, but there is no such option for PDO now.
Test script:
---------------
<?php
$attr[PDO::MYSQL_ATTR_SSL_CA] = "rootCA.pem";
//$attr[PDO::MYSQL_ATTR_SSL_SERVER_CN] = "the.real.server.cn";
try
{
$conn = new PDO("mysql:host=server.ip.here;port=3306;","test_user",
"my_password", $attr);
}
catch (Exception $e)
{
print "not ok\n";
throw $e;
}
print "ok of no exception\n"
?>
Expected result:
----------------
The test script requires mysql to be correctly setup to use ssl connection. I'm only posting
the client code here. And I'm hiding my real test ip.
Server certificate have CN "the.real.server.cn", and connection ip is some real ip
address. Since these two are different, the connection should fail.
After the attached patch, one can uncomment the PDO::MYSQL_ATTR_SSL_SERVER_CN line, and the
connection should succeed.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72235&edit=1
Thread (2 messages)